CVE-2026-10858

LOWCVSS 9.9 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-20: 209-20
Referenced assets2 URLs
Full discourse2 posts
  • ThreatWire@ThreatWire_

    🚨 CRITICAL: Two IBM MQ vulnerabilities can lead to remote code execution. CVE-2026-10747 (CVSS 10.0) is a pre-auth heap buffer overflow that could allow an unauthenticated remote attacker to execute arbitrary code through the MQ listener. CVE-2026-10858 (CVSS 9.9) is a heap buffer underflow affecting IBM MQ for HPE NonStop and can also lead to arbitrary code execution. ⚠️ Patch affected IBM MQ deployments immediately. 🔴 IBM has released fixes for both vulnerabilities. 🔗 IBM Security Bulletin https://www.ibm.com/support/pages/node/7284543 #IBM #IBMMQ #CVE #RCE #CyberSecurity #Infosec

    170176704
    1.5K followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    Critical IBM MQ vulnerabilities allow remote code execution. Learn how CVE-2026-10747 and CVE-2026-10858 hit 10.0 CVSS and require urgent patching. #IBMMQ #CVE202610747 #CVE202610858 #Cybersecurity #Infosec https://securityonline.info/ibm-mq-vulnerabilities-cve-2026-10747/

    00000364
    13.0K followersView on X

Explore more